Work at Vercel Sandbox? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 21 Sep 2026.
What it pays, by severity
Intake & responsiveness · last 90 days
Response targets it sets itself
A target the program declared, not a measurement of it being met.
Getting in the door
Over 31 days (229 snapshots): intake up 833 reports; response efficiency down 10 points.
See how this programme’s report load compares to others →
Reviews
0 publishedNo reviews yet.
Who this program credits
2 creditedResearchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.
| # | Researcher | Reputation | Recognised / submitted |
|---|---|---|---|
| 1 | h4rris0n | 7 | 0 / 0 |
| 2 | fkesheh | 0 | 0 / 3 0% |
Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 23 Sep 2026.
Scope
1 asset| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| Vercel sandbox | OTHER | ✓ bounty | Critical |